Machine learning powered user and entity behavior analysis
Abstract
The proposed system tracks user and entity behavior under 3 categories—time, count, and pattern. An event is composed of different fields that describe the event. For example, a log on event could have different fields like username, hostname, log on time, log on type, etc. An event is passed through one or more algorithms, depending on what kind of behavioral information needs to be tracked from the event. For example, a user logon event can be processed under the time category to detect whether the user is logging on at an anomalous time. It can also be processed under the pattern category to detect whether the user is logging on a host that does not fit into the user's regular log on pattern. The decision as to which events are to be processed under which category can be configured external to the system using domain knowledge.
Claims
exact text as granted — not AI-modified1 . A system comprising:
a historical data points model datastore; a model training engine coupled to and configured to train the historical data points model datastore; an inference engine coupled to the historical data points model datastore; wherein, in operation, the inference engine compares an event to a historical data points model in the historical data points model datastore to obtain a risk score and wherein the historical data points model datastore is updated by inference.
2 . The system of claim 1 wherein the model training engine includes a Robust Principal Component Analysis (RPCA) engine.
3 . The system of claim 1 wherein the model training engine includes a Markov chain engine.
4 . The system of claim 1 wherein the model training engine includes an Exponential Moving Average (EMA) engine.
5 . The system of claim 1 wherein an anomaly is associated with the risk score.
6 . The system of claim 1 wherein the risk score is a function of an expected value associated with an event and an actual value associated with an event.
7 . The system of claim 1 wherein an interval anomaly is associated with the risk score.
8 . The system of claim 1 wherein the risk score is a function of an interval threshold and a count.
9 . The system of claim 1 wherein the risk score is indicative of a pattern probability for an event that is greater than or equal to a threshold.
10 . The system of claim 1 comprising a clustering engine that clusters user or entity data for comparison to a peer group.
11 . The system of claim 1 comprising a peer group comparison engine that compares an event to a peer group to determine whether the event is anomalous relative to the peer group.
12 . The system of claim 1 comprising a risk score modification engine that decreases a risk score associated with an event and a user or entity if the user or entity is in a peer group for which the event is not anomalous.
13 . A method comprising:
training a historical data points model datastore; comparing an event to a historical data points model in the historical data points model datastore to obtain a risk score; updating the historical data points model datastore by inference.
14 . The method of claim 13 comprising using a Robust Principal Component Analysis (RPCA) model.
15 . The method of claim 13 comprising using a Markov chain model.
16 . The method of claim 13 comprising using an Exponential Moving Average (EMA) model.
17 . The method of claim 13 comprising clustering user or entity data for comparison to a peer group.
18 . The method of claim 13 comprising comparing an event to a peer group to determine whether the event is anomalous relative to the peer group.
19 . The method of claim 13 comprising decreasing a risk score associated with an event and a user or entity if the user or entity is in a peer group for which the event is not anomalous.
20 . A system comprising:
a means for training a historical data points model datastore; a means for comparing an event to a historical data points model in the historical data points model datastore to obtain a risk score; a means for updating the historical data points model datastore by inference.Join the waitlist — get patent alerts
Track US2021397903A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.